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We show how an arbitrary qubit rotation can be teleported, albeit probabilistically, using 1 e-bit 
of entanglement and one classical bit. We use this to present a scheme for implementing quantum 
secret sharing. The scheme operates essentially by sending a "secret" rotated qubit of information 
to several users, who need to cooperate in order to recover the original qubit. 
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I. INTRODUCTION 

f^*) i Hiding information may be one of the most useful applications of the growing science of quantum information, 

C^ beginning with the classical quantum cryptography work of Bennett et al. [1-2]. Since that work, many other 
CN i cryptographic problems have been addressed in a quantum context. We may cite, as especially relevant to this paper, 
the work of Hillery et al. [3] (see also Ref . [4] ) and Cleve et al. on quantum secret sharing [5] , and the very recent 
work by Terhal et al. [6] . One of the problems considered in [3] and [4] was how one party (Alice) could send a qubit 
of (quantum) information to two agents. Bob and Charlie, in such a way that they would have to cooperate in order 
QQ \ to recover the original message. Cleve et al. addressed the general problem of hiding the state of a (d-dimensional, 
with d arbitrary) quantum system, by encoding it into n shares, in such a way that k shares would be necessary to 
C^ ' recover the secret, and k — \ shares would contain no information whatever (a {k, n) threshold scheme). 
^ . In this paper, we present a scheme which allows n potential receivers of a qubit of quantum information to manipu- 

late, from a distance, its state (albeit without learning anything about it), in such a way that the original information 
becomes "hidden" (either completely or only partly, depending on the qubit 's initial state); then the qubit may be 
[^^ ' sent to one of them, and all of them must collaborate, by exchanging classical information, in order to recover the 
f^ \ full original state. If even one of them does not collaborate, the best they can do is to leave the qubit in a random 
T— I • rotated state. 

^^ \ Our method makes use of a maximally entangled (GHZ) state which Alice (the sender) shares with all the receivers. 

(— I . We show here that such a state allows the receivers to remotely "rotate" Alice's qubit; specifically, we show that an 
O ' arbitrary rotation about the "y" axis can be performed remotely, albeit probabilistically, at the cost of only one e-bit 
' , of entanglement and one bit of classical communication. It should be noted that Huelga et al. [7] first showed that the 
r^ ■ teleportation of an arbitrary unitary operation requires a minimum of 2 e-bits and 2 classical bits, and more recently 
Cd \ [8] they have also established the existence of restricted sets of operations which require fewer resources in order to be 
^ ■ teleported, either probabilistically or deterministically. Our result can be regarded as an additional example of this 
kind. 

The paper is organized as follows. The method for the teleportation of multiple rotations using a GHZ state is pre- 
sented in the following Section (Section II). The possible applications to secret sharing, including some considerations 
about the security of the scheme, are presented in Section HI. Section IV contains a brief discussion and conclusions. 
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II. TELEPORTATION OF ROTATIONS 

Suppose Alice holds a two-state particle (i.e., qubit), which is labeled by a and in an arbitrary unknown pure state 
a |0)^ -I-/3 |1)^ . We will show how n distant users can apply an arbitrary rotation to Alice's "message" qubit a through 
their local operations and classical communications. The "rotation" we have in mind is a formal rotation, by an angle 
^, in the two-dimensional Hilbert space of the qubit (see Eq. (4) below); it is, however, easy to show that the same 
operation corresponds, in Bloch-sphere terms, to a rotation by an angle 29 around the y axis, that is, to the action of 
the operator exp(— i(Tj,0). 

To begin with, Alice needs to share a (n -I- 1) -qubit GHZ state with n users [9]; the GHZ qubit belonging to Alice 
is labeled by 6, and the shared GHZ state is (|0)j |00...0) -I- \l)^^ |ll...l)). Thus, the state of the whole system is 

{a |0), + 13 |1) J ® (|0), I00...0) + |1), I11...1)) . (1) 
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By Alice first performing a Control-Rotation operation Rat [10] on her qubits a and b (with the control being qubit 

a) 

Rab = |00) (00| + |01) (Oil + |10) (10| - 111) (111 , (2) 

and then a Control- Not operation Cab, Eq. (1) will be transformed into 

{{a |00)„, + /3 |11)„,) I00...0) + {a |01)„, - /3 |10) J |ll...l)] . (3) 

Now each user performs a rotation operation on his/her qubit 

|0), ^ R (e,) |0), - COS0, |0)^ + sine, |1)^ , 

|1), -^ R (e,) \1)^^- sin e,\o)^+ cose, \1)^ (4) 

where subscript i stands for the ith user and 9i stands for the «th user's rotation angle. After that, we get, from Eq. 
(3), 



{am^, + P\U)^,}l[{cos0,\O)^ + sm9.,\l)^) 

n 

+ {a |01)„, - (3\10)J n (- sine, |0), + cos^, |1)^) (5) 



i=l 



Then, each user performs a measurement on his/her qubit. Suppose that m users (for simplicity, let them be the 
users labeled by 1, 2, ..., m) measure their qubits in the |0) while n — m users measure their qubits in the |1). From 
Eq. (5), we have 



(aioo)^,+/?iiiu)n'^°^^» n «ine, 

i—1 i—m-\-l 

m n 

-f(a|01),,-/3|10),,)(-l)"nsin^^ n c°«^» (6) 



i—1 z— m+l 

A simple SWAP operation on the qubits a and h by Alice will transform Eq. (6) as follows 



(a|00)„, + /3|ll)„,)ncose, n ^in^* 

m n 

+ {a\l0)^,~P\0l)J{-ir\{s\n6, [] cos^, (7) 

i—1 2— m+l 

The above equation (7) can be rewritten as 

«|0)J^)+/3|l)J^') (8) 

where 



|V')-n^°^^« n sine, |0)^ + (-ir[] sine, W cose,|l>^, (9) 

■i—1 z— m+1 i=l 2— m+l 

m n m n 

|V')-n^°^^« n sine,|l)„-(-ir[]sine, W cose,|0)^ (10) 



i—1 i— m+1 2—1 i—m-\-l 



Now Alice performs a Hadamard transform on her qubit b : |0) ^ (|0) + |1)) and |1)^(|0) — |1)). After that, Eq. 
(8) wiU be 

[«(|0), + |1),)|^)+/3(|0),-|1),)|V')] (11) 



One can easily find from Eq. (11) that if Alice performs a measurement on her qubit &, for the measurement outcomes 
0) and |1), Eq. (11) will be, respectively 



|0), : a|V)+/3|V'), 

|1), : a IV) -/31V'') 

Substituting Eqs. (9) and (10) into Eqs. (12) and (13), and normalizing them, we have 

|0), : a(A|0), + B|l)J + /3(A|l)„-i?|0)J, 

|1), : a{A\0)^+ B\1)J - PiA\l)^- B\0)J , 

where the coefficients A and B are 



A 



B = 



n"iCos6',nr=m+iSin( 



(nr=i cos 0, riLm+i sin o^) + (n™ 1 sm e, riLm+i cos 0, 



li—m-\-l 



(-irnr=isin^.n: 



i—m-\-l 



COS 9i 



iUZi cos 9, ntm+i sin 0^) + (nili sin 6*, ULm+i cos 0. 



(12) 
(13) 

(14) 
(15) 



(16) 
(17) 



Noting that A and B satisfy A"^ 
be written as 

|0), : 
|1). : 
where 



B^ = 1, we can define A — cos4> and B = sin(/). Thus, Eq. (14) and Eq. (15) can 



a(cos</)|O)„ + sin0|l)J+/3(- 
a(cos<^|O)„ + sin0|l)J-/3(- 



Sim 
sin I 



.|O)„+cos0|l)J, 
'|O)a+cos0|l)J 



B 

A 



tan ^ —- = tan ^ 



(-l)"JJtan6l, Yl cote*. 



i=l 



«— rn+1 



(18) 
(19) 



(20) 



The above results (18-19) imply that when the qubit b is measured in the |0) state, the resulting state (18) of qubit a 
is the same as the state R {(j)) (a |0)^ + /3 11)^), i.e., the state created by Alice directly performing a rotation operation 
R {4>) on the initial state a\0) + P\l) of qubit a. This means that in the case when the qubit b is measured in the |0) , 
the above n users apply a rotation operation R {(j)) to a distant qubit a through their local operations. From Eq. (20), 
the rotation angle (j) depends on each user's rotation angle. On the other hand, when the qubit b is measured in the |1) 
state, the resulting state (19) of qubit a is the same as the state created by Alice directly performing a Pauli rotation 
az (i.e., a phase- flip operation) and then a rotation operation R{'k + (j)) on the initial state a |0)+/3|1) of qubit a. This 
shows that in the case when the qubit b is measured in the |1) , the above n users apply a rotation operation i? (tt -I- 0) 
together with a Pauli rotation ctz to a distant qubit a. Alternatively, for this measurement outcome, Alice could 
apply a Cz to the qubit a, with the result that its state will become R{tt — (f>) (a |0) + f3 |1)) . In terms of Bloch-sphere 
rotations, the first possibility (state |0)) corresponds to a rotation by an angle 20 around the y axis, whereas the 
second possibility (state |1)), after Alice applies the Cz operation, is a rotation by an angle 27r — 20, or, alternatively, 
a rotation by an angle 20 in the opposite direction. 

In previous work [7] , Huelga et al. have shown that if Bob wants to perform an arbitrary unitary remote operation 
on Alice' particle. Bob and Alice need to share two EPR pairs (i.e., two e-bits), and also two classical bits are required. 
More recently [8] they have also considered the resources needed to perform restricted sets of operations (in particular, 
Bloch-sphere rotations), and found that for two classes of operations, namely, rotations (by any angle) around the z 
axis, or rotations by tt degrees around any axis lying on the x — y plane, only one bit of entanglement and 2 classical 
bits (one in each direction) are needed, if one knows ahead of time what kind of transformation the other party is 
trying to implement. 

In our case, if we restrict ourselves to just two parties, Alice and Bob, we have n = 1, and the GHZ state is just 
a two-qubit Bell state. Inspection shows that, if Alice knows the result of Bob's measurement on his qubit, she can 
(by applying suitable local operations, such as phase and/or bit flips) put her qubit in a state which can be written 
compactly as exp{±iay9)\)a, where is the rotation angle chosen by Bob, |)a is her qubit's initial state, and (depending 
on the result of her own measurement on qubit b) she will know whether the -I- or the — sign applies in this expression. 
In other words, for this special case, one e-bit and one classical bit are enough to remotely effect a rotation of the 
right magnitude, but its direction (clockwise or counterclockwise) is random, depending on the outcome of Alice's 
measurement of her qubit b. As will be argued in the following section, in spite of its randomness, it is possible that 
this result might be useful in some contexts. 



III. APPLICATION TO SECRET SHARING 

A practical application for the above "teleporting" of a rotation may be a modification of the quantum secret 
sharing ideas first presented by Hillery et al. [3]. In their scheme, they show how to obtain quantum secret sharing 
by splitting quantum information among several parties, in such a way that only one of them is able to recover the 
qubit exactly provided all the other parties agree to cooperate. However, we note that, in general, each party still can 
get partial quantum information in this scheme. According to the protocols in Ref. [3], when Alice's qubit is in the 
state a\0) + (3\1), the n parties who receive the information are left sharing an n-qubit entangled state of the form 
a|00...0) ±/3|ll...l) or a|ll...l) ±/3|00...0) (depending on Alice's Bell-state measurement results). From this one 
can get the density operator for each qubit pi = p2... = Pn = \af |0) (0| + |/3|^ |1) (1| or |a|^ |1) (1| + |/3|^ |0) (0| . This 
expression shows that, even without cooperating with others, each party can still get some amplitude information 
about Alice's qubit, although neither of them can independently recover the full original state. 

In the following, we will present a new scheme for quantum secret sharing, which we call "receiver-encoded" secret 
sharing. As we will show, the present scheme is actually not based on splitting quantum information; rather, it works 
essentially through each receiver "encoding Alice's message qubit" by their respective rotation angles and then by 
Alice sending her rotated qubit to one of the parties. A nice property of our scheme is that, if the method presented 
in the previous section is used, the receivers can perform the remote rotation of Alice's qubit without having access 
to any of the information contained in it (whether individually or jointly); this can be seen immediately from the fact 
that, when the overall state of the system is given by (3) above, the reduced density operator for the n receivers is 
just |00...0)(00...0| + |11...1)(11...1|, independent of a and /3. 

Suppose then that the n receivers follow the procedure in the previous section to remotely rotate Alice's qubit a, 
after which she sends it to one of them (e.g.. Bob). The state of the rotated qubit a is given by Eqs. (18) and (19). 
Noting that the rotation operator R (0) and the Pauli operator CTz are given by 

we have 

i?(-0)i?((/)) =/, (22) 

(T^R{-TT-(j))R{n + (f>)a^ = I (23) 

where / is the identity. Thus, if Bob wants to recover the original state a |0)^ -|- /3 |1)^ of qubit a from Alice, (a) for 
the case when Alice measures the qubit b in the |0), he may perform a unitary operation i?(— 0) (i.e., the rotation 
with the angle —(f>) on the qubit a; (b) for the case when the qubit b is measured in the |1) , he can perform a unitary 
operation CTzi?(— tt — (f)) (i.e., first, a rotation with the angle — tt — (f>, and then a Pauli rotation ct^) on qubit a. 

From the above description, one can see that Bob's recovery operation depends on Alice's measurement outcomes, 
and that the angle (f> (given by Eq. (20)) depends on each receiver's rotation angle and each receiver's measurement 
outcome. Thus, in order for Bob to recover the original state of qubit a, (a) Alice needs to send her measurement 
outcomes to Bob through a classical channel, and (b) all the other receivers need to tell Bob their rotation angles 
and their measurement outcomes through classical communications. If any other receiver does not collaborate with 
Bob, he has no way to calculate the value of (j> accurately, and thus he can do no better than to leave the qubit in a 
random rotated state. 

We now need to ask the following question: suppose that we have a qubit and apply to it a random rotation; how 
well, on the average, have we "hidden" the information initially contained in it? One way to answer this is to look 
at the average fidelity between the rotated qubit and the original one; if the average is 1/2, then the rotated qubit 
might as well be a totally random state; otherwise there is some "trace" of the original state left in the rotated state. 

If the initial state is of the general form 

|V) = cos||0)+e^'^sin||l), (24) 

the rotated state is of the form 

/ d d \ ( -d ■ d \ 

R{(j)) \Tp) = cos - cos - e**^ sin - sin (/) 1 |0) + cos - sin + e"^ sin - cos </) 1 |1) (25) 

and the fidelity is 

J^id,(p,<j)) = |(V'|i?(0)|V')l^ =cos^(t> + sm^(t>am^i}sm^ip. (26) 



If this is averaged over i), ip, and (j>, assuming uniform (random) distributions, the resuh is 5/8 = 0.625, greater than 
the relative fidehty between the initial state and the totally random state. On the other hand, for the special class of 
qubits for which tp = 0, we have 

T{i^,ip,(j))^cos'^(J3 (27) 

and this clearly averages to 1/2. 

Note that for the qubit rotated by the many receivers, as above, the distribution of the overall rotation angle (j) is 
not uniform, but one should still have ^cos^ 0) = (sin^ 0) = 1/2, since, for instance, cos^ (j) = 1/2 + (cos 20) /2 and 
the average of cos 2(f> is zero for any distribution of (j) (between and ir) which is symmetric around 7r/2, which will 
be the case for the distribution of the overall rotation angle (j) (given by Eq. (20)) if all the distributions for 0i, 02, ■■■ 
have the same symmetry. Thus, for the special case of qubits of the form (24) with ip = 0, our method produces a 
qubit which, on average, bears no more resemblance to the initial qubit than a totally random state. 

For qubits with </? ^ 0, as stated above, the situation is different. In particular, for the special cases \tp) — 
4= (|0) ± i |1)) , the rotation leaves the qubit invariant except for a phase change (cf. eq. (26) with d = ^, p = ±-|; 

this is natural, since these are the eigenstates of CTj,). Hence, these special qubit states are not "hidden" at all. We 
have, therefore, a "restricted" secret sharing scheme, in a sense complementary to the one of Hillery et al. [3]: in 
their scheme, the sharers could get information on the original qubit's amplitude, in ours they could get information 
on the phase. The main difference is that in our scheme only one user actually has a physical qubit (which may in 
some way be regarded as safer). 

Although we shall not attempt here a comprehensive study of the security of the scheme against all possible forms 
of eavesdropping and/or cheating, we believe that it is probably quite secure, for several reasons. First, as pointed out 
above, before Alice actually sends her qubit to one of the receivers they have no information at all, either individually 
or jointly, about its state (assuming that the overall state of the system is given by Eq. (3)); from here it also follows 
that an eavesdropper cannot hope to gain information about Alice's qubit by entangling a particle with any of the 
receivers'. Second, the qubit Alice sends to (say) Bob is basically useless (modulo the reservations just discussed above) 
without the classical information possessed individually by all the "receivers;" hence, even if Eve were to intercept 
the qubit intended for Bob, and replace it by a fake, and somehow eavesdropped on the (classical) communication 
channels through which all the other parties disclose to Bob their rotation angles and measurement outcomes, she 
would still not be able to recover the qubit's original state without access to Bob's own information (his rotation angle 
and measurement outcome), which he does not have to send to anybody, and hence may be considered secure. It is 
conceivable that an eavesdropper might get partial information on the rotation angles and measurement outcomes of 
all the receivers by entangling enough particles with their respective qubits, but presumably such entanglement could 
be detected by tests conducted on "sample" GHZ states initially shared by Alice and the other parties, as discussed 
by Hillery et al. [3]. 

IV. CONCLUSION 

We have presented a (probabilistic) method to teleport a certain class of rotations and proposed a possible appli- 
cation to a "restricted" quantum secret-sharing scheme. A special feature of our secret-sharing concept is that only 
one recipient actually gets a qubit of quantum information; all the other parties have only the classical information 
of their rotation angles, known only to themselves. Thus the original quantum information is not really split into 
"shares" : the quantum channel, consisting of the shared GHZ state, is used only for the receivers to rotate the original 
qubit by their local operations known only to themselves (and without gaining any information on the original qubit 
state in the process). Although our scheme is less general than, for instance, the threshold schemes of Ref. [5], we 
believe it is of some interest nonetheless, especially because of its relatively straightforward nature. 
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